sk122519 - Cloud Firewall for AWS - Amazon GuardDuty Integration

Cloud Firewall for AWS - Amazon GuardDuty Integration

Solution

Table of Contents:

(1) Overview

Amazon GuardDuty is a managed threat detection service that continuously monitors for malicious or unauthorized behavior to help you protect your AWS accounts and workloads. Read more about Amazon GuardDuty here.

When GuardDuty identifies a threat, a CloudWatch Event triggers the execution of the Lambda function deployed via a CloudFormation template. The Lambda function will then tag the EC2 instance associated with the threat.

Check Point Cloud Firewall (formerly CloudGuard Network Security) applies the security policy, and the Security Gateways enforce it automatically, without manual intervention, on instances tagged with the tag key you have chosen. This is done to mitigate any risk immediately when it appears (Check Point Security Management and your AWS environment are fully synced using CloudGuard Controller).

This solution is Check Point's recommended practice: a CloudFormation template creates a CloudWatch Event that matches GuardDuty Findings and a Lambda function that is triggered by the event and tags the suspicious instances. This allows Check Point and AWS mutual customers to benefit from a self-service, automatic, and adaptive solution that detects and prevents malicious activity in real time.

(2) Prerequisites

  1. Amazon GuardDuty is enabled in the AWS account.
  2. Monitored resources are protected by Check Point Cloud Firewall Gateway(s), managed with a Smart Management Server, and Cloud Firewall for AWS is configured to integrate with the AWS account. Read more on how to configure CloudGuard Controller to integrate with your AWS account here.
  3. One of the EC2 instances in the environment is tagged with a tag of your choosing. Note the tag key, as it will be used later in the configuration. e.g. chkp-GuardDuty.

(3) Configuration of the Security Policy

Configure a Security Policy to drop traffic to and from an AWS EC2 instance identified as suspicious by GuardDuty:

  1. Open Smart Console.
  2. Under the relevant policy, create a new rule in the desired position.
  3. In the newly created rule, if you wish to block outgoing traffic from the identified instances, click on the plus icon in the Source column. If you wish to block incoming traffic to the identified instances, click on the plus icon in the Destination column. If you wish to block both outgoing and incoming traffic, create two separate rules.
  4. Click on the 'Import...' icon and choose your AWS Data Center:
  5. Under Tags, find the key of the tag created in section (2), step 3. Make sure to choose the entry with Tag Key in the Type in Server column, and not Tag Value.
  6. Click on the plus icon to the left of the entry.
  7. In the Action column, select Drop.
  8. Configure the remaining rule and install the policy.

(4) Register Check Point's GuardDuty Lambda function to tag suspicious EC2 instances

Deploy the Check Point CloudFormation template to register the Lambda function that tags suspicious instances identified by Amazon GuardDuty with the predefined tag key:

  1. Use the following CloudFormation template to deploy the Check GuardDuty Lambda:

  2. Fill the Tag key field with the tag key you have used in section (2), step 3. This will be used as the key in the key-value tag added to EC2 instances that are identified by GuardDuty. The tag value will contain the reason provided by GuardDuty for issuing the finding. Read more about Amazon GuardDuty Findings here.

  3. Choose the severity of GuardDuty alerts that will trigger the Lambda function. Read more about Severity Levels for GuardDuty Findings here.

  4. Deploy the template.

(5) Reinstating traffic for a blocked instance

The Lambda function tags the EC2 instance associated with the threat found by Amazon GuardDuty as follows:

If you have inspected the reason provided by GuardDuty as described in the tag value and wish to reinstate traffic for the EC2 instance, manually remove the tag:

  1. Open the Amazon EC2 console.
  2. In the left navigation pane, choose Instances.
  3. Select the instance for which you wish to reinstate traffic.
  4. Select the Tags tab.
  5. Click Add/Edit Tags.
  6. Click on the X icon to the right of Tag key you have specified.
  7. Click Save.

No additional configuration is required on the Management Server or the Security Gateways.